Skip to main content
Category: Regulatory Frameworks

SEC Cyber Disclosure Rules

Also known as: SEC Cybersecurity Disclosure Rule, SEC Cyber Incident Reporting Rule, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rules
Simply put

The SEC Cyber Disclosure Rules are U.S. Securities and Exchange Commission requirements that direct public companies to tell investors about serious cybersecurity incidents and about how they manage cyber risk. Companies must report a cybersecurity incident once they judge it to be material, and must also describe their cyber risk management and governance in their annual reports. The rules aim to make such disclosures more transparent, consistent, and timely across companies.

Formal definition

A set of rules adopted by the U.S. Securities and Exchange Commission in 2023 (effective December 2023) to standardize and enhance registrant disclosures regarding cybersecurity. The incident-disclosure component requires companies to disclose material cybersecurity incidents on Form 8-K, typically within four business days of determining that an incident is material; the trigger is the materiality determination rather than the date of discovery or occurrence. The periodic-disclosure component requires annual Form 10-K disclosures describing the company's processes for assessing, identifying, and managing material cybersecurity risks, along with related strategy and governance information, including board and management oversight. These rules govern what and when public registrants must disclose to investors; they are a securities-disclosure obligation and do not themselves prescribe specific technical security controls, mandate a particular cybersecurity framework, or confer any certification or assurance of a company's security posture. Scope is limited to SEC registrants subject to U.S. federal securities reporting; requirements and enforcement expectations may differ for foreign private issuers, smaller reporting companies, and IPO registrants, and this rule set is distinct from cyber-disclosure or breach-notification regimes in other jurisdictions.

Why it matters

For third-party and supply chain risk professionals, the SEC Cyber Disclosure Rules change the information environment around the public companies they rely on as suppliers, service providers, and business partners. Because the rules require registrants to disclose material cybersecurity incidents on Form 8-K and to describe their cyber risk management, strategy, and governance in annual 10-K filings, they create a more transparent, consistent, and timely stream of publicly available signals that can inform vendor due diligence and ongoing monitoring. A supplier's 8-K incident disclosure or its annual description of cyber governance can supplement, but does not replace, direct assessment through questionnaires or contractual reporting arrangements.

The rules also carry a subtle but important limitation for risk teams: the incident-disclosure trigger is the company's own materiality determination, not the date an incident was discovered or occurred. This means disclosures are shaped by each registrant's judgment and are oriented toward investors' interests, so they may not surface incidents a customer or partner would consider operationally significant, and they may not capture the timing that matters most for supply chain response. The 10-K disclosures describe processes and governance rather than certifying security posture, so they should be read as context, not assurance.

Because the scope is limited to SEC registrants subject to U.S. federal securities reporting, coverage is uneven across a supply base. Privately held suppliers, and vendors based outside the United States, are not captured in the same way, and requirements and enforcement expectations may differ for foreign private issuers, smaller reporting companies, and IPO registrants. Risk professionals should therefore treat these disclosures as one input among several rather than a comprehensive early-warning system.

Who it's relevant to

Third-Party Risk and Vendor Due Diligence Teams
Teams assessing public-company suppliers can use 8-K incident disclosures and 10-K cyber governance descriptions as publicly available inputs to due diligence and ongoing monitoring. These disclosures supplement rather than replace direct assessment methods such as questionnaires and contractual reporting, and because they reflect the registrant's own materiality judgment oriented toward investors, they may not surface every incident relevant to a customer's operations.
Compliance and Legal Functions
For organizations that are themselves SEC registrants, compliance and legal teams are responsible for interpreting the materiality trigger, coordinating Form 8-K reporting typically within four business days of a materiality determination, and preparing the annual 10-K disclosures on cyber risk management, strategy, and governance. They should note that requirements and enforcement expectations may differ for foreign private issuers, smaller reporting companies, and IPO registrants.
Security and Governance Leaders
CISOs, boards, and management involved in cyber oversight are directly implicated by the 10-K requirement to describe processes for assessing, identifying, and managing material cybersecurity risks, along with board and management oversight. These leaders should recognize that the disclosures describe governance and process rather than certifying security posture, and that the rules do not mandate any specific technical controls or framework.
Supply Chain Resilience and Monitoring Teams
Teams monitoring extended supply networks can incorporate public disclosures from registrant suppliers into their signal-gathering, while accounting for scope gaps: privately held and non-U.S. suppliers are not captured in the same way, and the materiality-based timing may not align with operational response needs. These disclosures are best treated as one input among several rather than a comprehensive early-warning mechanism.

Inside SEC Cyber Disclosure Rules

Material Cybersecurity Incident Disclosure
A requirement for registrants to disclose cybersecurity incidents determined to be material, typically describing the nature, scope, and timing of the incident and its material impact or reasonably likely material impact on the registrant. This centers on the materiality determination rather than on every incident detected, and the disclosure obligation is generally triggered without unreasonable delay after the materiality determination is made.
Materiality Determination Process
The assessment of whether an incident is material, which drives the timing and existence of a disclosure obligation. Materiality is evaluated in light of the total mix of information available to a reasonable investor and is not defined by a fixed numeric threshold; the clock for disclosure is typically keyed to when materiality is determined, not to the date of discovery.
Cybersecurity Risk Management, Strategy, and Governance Disclosure
Periodic disclosure of the registrant's processes for assessing, identifying, and managing material cybersecurity risks, including how the board oversees such risks and the role of management. This is a governance and process disclosure and does not itself prescribe specific security controls or attest to their effectiveness.
Third-Party and Supply Chain Considerations
Disclosure processes are expected to consider risks arising from the use of third-party service providers, since a material incident may originate with or propagate through vendors. This reflects a first-order acknowledgment of third-party exposure but does not, on its own, mandate specific vendor monitoring practices or extend visibility into fourth-party or Nth-party relationships.
Scope of Applicability
The rules apply to registrants subject to U.S. securities reporting obligations, with certain accommodations for smaller reporting companies and separate treatment for foreign private issuers. They govern public disclosure to investors and are distinct from sector-specific breach-notification laws that address obligations to regulators or affected individuals.

Common questions

Answers to the questions practitioners most commonly ask about SEC Cyber Disclosure Rules.

Do the SEC cyber disclosure rules require companies to publicly report every cybersecurity incident involving a third party?
No. The disclosure obligation is generally tied to incidents determined to be material to the registrant, not to every incident. An incident affecting a third-party service provider or vendor may or may not rise to the level of a required disclosure, depending on the registrant's materiality assessment. The rules focus on the impact to the registrant rather than mandating disclosure of all events in the supply chain, and they do not require naming or itemizing every affected vendor.
Does complying with the SEC cyber disclosure rules mean a company's third-party risk program is adequate or certified?
No. These rules are disclosure requirements addressed to registrants; they govern what and when a company must tell investors, not whether its underlying third-party risk controls are effective. Disclosure is not a certification, an attestation of program quality, or independent verification that vendor risk is being managed well. A company can satisfy disclosure obligations while still having gaps in its third-party oversight, and conversely a strong program does not exempt a registrant from disclosure duties.
How does an incident originating at a third-party provider factor into a materiality determination?
In many programs, an incident at a service provider or vendor is assessed for its impact on the registrant using the same materiality lens applied to internally originated incidents. This typically requires the registrant to obtain enough information from the affected third party to evaluate scope and impact, which can be difficult where contractual notification terms or visibility beyond the first tier are limited. Where the registrant cannot promptly gather sufficient facts, the materiality assessment may need to proceed on available information and be revisited as more is learned.
What contractual provisions help support timely disclosure when a vendor is involved?
Programs commonly rely on incident notification clauses that specify timeframes, the type of information the vendor must provide, and cooperation obligations during investigation. Depending on the risk tier, contracts may also address audit or information rights, points of contact, and escalation. These provisions support the registrant's ability to assess materiality on a workable timeline, but they do not guarantee complete or timely vendor information, and visibility into fourth-party or Nth-party dependencies is often not covered.
How do these disclosure obligations interact with a company's broader third-party monitoring processes?
Disclosure readiness typically depends on ongoing monitoring and incident intake processes that can surface vendor-related events quickly and route them into materiality evaluation. Point-in-time onboarding due diligence alone is generally insufficient for this purpose, since incidents arise after onboarding. Coordinating security, legal, disclosure, and vendor management functions is often necessary so that relevant third-party events reach the people making disclosure judgments.
Do these rules apply to all organizations that have third-party relationships?
No. These are U.S. securities disclosure requirements applicable to registrants subject to SEC reporting; they are not a universal standard for all companies or all vendors. Organizations outside that scope, or in other jurisdictions, may face different regulatory expectations around cyber incident reporting. Companies operating across regions should treat these rules as one regime among several rather than a globally uniform obligation.

Common misconceptions

The rules require disclosure of every cybersecurity incident within a fixed number of days of discovery.
The disclosure obligation is generally tied to a materiality determination, not to the date an incident is discovered. Immaterial incidents typically do not require this disclosure, and the timing is anchored to when materiality is determined rather than to detection.
Disclosing cybersecurity governance and risk-management processes attests that a registrant's security controls are effective.
The governance and strategy disclosure describes processes for identifying and managing risk; it is a description of process, not an attestation of control effectiveness and not a guarantee that any control prevents or mitigates a given incident.
Because third-party risk is referenced, the rules impose a specific vendor due diligence or continuous monitoring program.
The rules ask registrants to consider third-party service provider risks within their processes but do not prescribe a particular TPRM methodology, and they do not extend required visibility beyond direct relationships into fourth-party or lower-tier dependencies.

Best practices

Establish a documented, repeatable materiality determination process with defined decision-makers and criteria, so the timing of any disclosure obligation can be identified and evidenced without unreasonable delay.
Integrate third-party service provider incidents into incident response and materiality workflows, recognizing that a material incident may originate with a vendor while acknowledging limited visibility beyond the direct relationship.
Align internal escalation between security, legal, and disclosure functions so that incident facts reach those responsible for the materiality assessment in a timely manner.
Distinguish these investor-facing disclosure obligations from sector-specific or jurisdictional breach-notification requirements, and maintain separate tracking for each so overlapping timelines are managed correctly.
Prepare governance and risk-management process descriptions that accurately reflect actual practices, avoiding language that implies control effectiveness or certification the rules do not confer.
Account for applicability differences, including accommodations for smaller reporting companies and separate treatment for foreign private issuers, when scoping the program to a specific registrant.
Promotional banner for the Penetration Report Template Kit